Report by Cloud Security Alliance (CSA)

Identity and Access Gaps in the Age of Autonomous AI

14 FINDINGSPublished Mar 24, 2026
View Original Report →

Key Findings

57% of organizations report moderate or high confidence in identity scoping for AI agents.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Identity ManagementRisk AssessmentAI AgentsIdentity Scoping

74% of organizations say AI agents often receive more access than necessary.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Access ControlPrivilege ManagementAI Agents

Responsibility for AI agent identity and access is fragmented: 28% of organizations assign primary ownership to security leads, 21% to development/engineering, 19% to IT, and 9% to IAM teams.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AI Agent GovernanceIdentity and Access ManagementOrganizational RolesAI Agents

22% of organizations report that access frameworks are applied very consistently to AI agents.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Access ControlAI AgentsIdentity Management

68% of organizations cannot clearly distinguish between human and AI agent activity.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AI AgentsHuman vs AI Agent Activity

52% of organizations use workload identities for AI agents, 43% rely on shared service accounts, and 31% allow agents to operate under human user identities.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Identity ManagementAccess ControlAI AgentsHuman User Identities

49% of organizations disable identities or revoke tokens as containment actions, 42% terminate the compute environment where an agent runs, and 33% remove or modify access policies in real time.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Identity ManagementAccess Control

73% of organizations expect AI agents to become vital within the next year.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AI Agents

AI agents operate across enterprise workflows: 67% are task automation agents, 52% are research agents, 50% are developer-assist agents, and 50% are security or monitoring agents.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AI AgentsEnterprise

85% of organizations use AI agents in production environments.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AI AgentsProduction Environments

79% of organizations believe AI agents create new access pathways that are difficult to monitor.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Access ControlAccess MonitoringAI AgentsAccess Pathways

32% of organizations are uncertain how much time is required to implement and maintain authentication or credential handling for a typical AI agent.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AuthenticationAI AgentsIdentity Management

52% of organizations say AI agents inherit access originally intended for humans or other systems at least sometimes.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
Identity ManagementPrivilege ManagementAccess ControlAI AgentsHuman User Identities

33% of organizations do not know how often AI agent credentials are rotated.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·4mo ago
AI AgentsAI Agent CredentialsIdentity ManagementCredential Rotation